What is CVE-2026-18352?
CVE-2026-18352 is a critical vulnerability in the User Access Manager plugin for WordPress. It involves Directory Traversal via the 'uamgetfile' parameter, allowing unauthenticated attackers to read arbitrary files on the server. All plugin versions up to and including 2.3.15 are affected, requiring immediate patching.
Azərbaycanca: CVE-2026-18352, WordPress-in User Access Manager plaginində aşkar edilmiş kritik bir boşluqdur. Bu qüsur, 'uamgetfile' parametri vasitəsilə autentifikasiya olmamış şəxslərə serverdə ixtiyari faylları oxumağa imkan verən Directory Traversal zəifliyidir. Plaginin 2.3.15 daxil olmaqla bütün versiyalarını təsir edir və dərhal yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What action does the CVE-2026-18352 vulnerability in the User Access Manager plugin allow unauthenticated individuals to perform?
CVE-2026-18352 is a Directory Traversal vulnerability in the User Access Manager plugin for WordPress, allowing unauthenticated attackers to read arbitrary files on the server via the 'uamgetfile' parameter.
Which versions of the User Access Manager plugin are affected by CVE-2026-18352?
The CVE-2026-18352 vulnerability affects all versions of the User Access Manager plugin up to and including version 2.3.15.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.